ATT&CKReferencesJoint Cybersecurity Advisory LockBit JUN 2023

Joint Cybersecurity Advisory LockBit JUN 2023

CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareLockBit 3.0

LockBit 3.0 can identify and terminate specific services.

T1070.004
File Deletion
MalwareLockBit 3.0

LockBit 3.0 can delete itself from disk.

T1480
Execution Guardrails
MalwareLockBit 3.0

LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list.

T1486
Data Encrypted for Impact
MalwareLockBit 3.0

LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms.

T1489
Service Stop
MalwareLockBit 3.0

LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption.

T1490
Inhibit System Recovery
MalwareLockBit 3.0

LockBit 3.0 can delete volume shadow copies.

T1569.002
Service Execution
MalwareLockBit 3.0

LockBit 3.0 can use PsExec to execute commands and payloads.

T1614.001
System Language Discovery
MalwareLockBit 3.0

LockBit 3.0 will not affect machines with language settings matching a defined exlusion list of mainly Eastern European languages.

T1685
Disable or Modify Tools
MalwareLockBit 3.0

LockBit 3.0 can disable security tools to evade detection including Windows Defender.

T1685.005
Clear Windows Event Logs
MalwareLockBit 3.0

LockBit 3.0 can delete log files on targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.